Vulnerability Report: GO-2023-2000
- CVE-2023-39533, GHSA-876p-8259-xjgg
- Affects: github.com/libp2p/go-libp2p
- Published: Aug 08, 2023
- Modified: May 20, 2024
Large RSA keys can lead to resource exhaustion attacks. With fix, the size of RSA keys transmitted during handshakes is restricted to <= 8192 bits.
For detailed information about this vulnerability, visit https://github.com/libp2p/go-libp2p/security/advisories/GHSA-876p-8259-xjgg.
Affected Packages
-
PathGo VersionsSymbols
-
before v0.27.8, from v0.28.0 before v0.28.2, from v0.29.0 before v0.29.1
Aliases
References
- https://github.com/libp2p/go-libp2p/security/advisories/GHSA-876p-8259-xjgg
- https://go.dev/issue/61460
- https://github.com/libp2p/go-libp2p/commit/0cce607219f3710addc7e18672cffd1f1d912fbb
- https://vuln.go.dev/ID/GO-2023-2000.json
Feedback
See anything missing or incorrect?
Suggest an edit to this report.